Legal
Privacy Policy
Last updated: 2026-09-01
Bitfront AB, Swedish Registration number 559155-7912, Mellanvägen 5, 136 70 Vendelsö, Sweden, is the data controller for personal data processed under this policy. We collect personal data only when you have given consent or when it is necessary to deliver the service. This policy covers use of bytesafe.dev and docs.bytesafe.dev.
This policy applies where you use the service without a separately signed agreement. Where Bitfront AB and your organization have entered into a written agreement covering the service, that agreement applies instead of this policy.
1. Data collection
What data we collect depends on how you use the service.
1.1 Automatic data collection
When you visit bytesafe.dev or docs.bytesafe.dev, or use the service, we may automatically collect technical data: cookies, IP addresses, browser version, locale, and usage metrics, to understand and improve how the service is used.
Two tools measure this. PostHog provides product and site analytics and sets cookies; it runs only with your consent. Vercel Web Analytics counts page views without cookies or on-device storage, processing your IP address in transient form to distinguish visits, without building a profile or tracking you across sites, on the basis of our legitimate interest. You can object at any time using the contact address below. See our Cookie Policy for the cookies each sets.
1.2 Data you provide directly
We collect data you provide when registering an account, subscribing to a plan, or contacting us for support.
1.2.1 Registered users
Creating a Bytesafe account requires at minimum an email address.
1.2.2 Paying customers
Subscribing to a paid plan requires billing information. This is collected and processed by our payment provider (Stripe) on our behalf. We do not store full payment card details.
1.2.3 Support correspondence
If you contact us for support, we may retain that correspondence, including your email address, for future reference.
1.2.4 Prospect and enquiry data
When you submit a contact, demo request, or evaluation form on bytesafe.dev or docs.bytesafe.dev, we collect the information you enter. Depending on the form, that is your name, business email address, company, preferred deployment model, organization size, the products you are interested in, your use case, and any free-text message you write. Do not include confidential or sensitive information in the message field.
Submitting a form sends the contents to a private channel in our internal Slack workspace, where a team member reviews and replies. Slack is a subprocessor for this; see our Subprocessors page for its location and the transfer mechanism.
We process this data on the basis of our legitimate interest in responding to a business enquiry and following it up. You can object to that processing, or ask us to delete the data, at privacy@bytesafe.dev.
2. How we use data
We use collected data to provide, maintain, and improve the service. Specifically:
- Operate and secure the service
- Respond to support requests
- Analyze aggregate usage patterns to improve the product
- Send transactional email (account notices, invoices)
We will ask for your consent before using data for any purpose not listed here.
3. Data sharing
We do not sell your data. We share data only in these cases:
- With subprocessors needed to operate the service (see our Subprocessors page)
- To process payments, with our payment provider
- With Slack (Salesforce, Inc.), which receives contact and demo form submissions so we can respond to them
- When required by law, or to prevent fraud or harm
- If Bitfront AB is acquired, we will notify you before any data transfers to a new owner
We may share non-identifiable aggregated data with partners.
4. Legal basis for processing
We process personal data on these legal bases: performance of a contract (account administration, billing, support), legitimate interests (security, fraud prevention, cookieless usage measurement, and responding to business enquiries), consent (functional, analytics, and marketing cookies, see our Cookie Policy), and legal obligation (tax and accounting records).
5. Your rights
Under GDPR you have the right to access, correct, delete, or export your personal data. Deleting your account removes personal data subject to retention obligations under applicable law.
You also have the right to lodge a complaint with Integritetsskyddsmyndigheten (the Swedish Privacy Protection Authority), or with the supervisory authority in your country of residence.
To exercise any right or ask questions, contact us at privacy@bytesafe.dev.
6. Data security
We encrypt data in transit and at rest, and restrict administrative access to staff who need it to do their job. See our Security page for detail on our technical and organizational measures.
7. Data retention and deletion
You can export your data during your subscription and for 30 days after it ends. We delete your data from our production systems within 30 days after that export period. Data held in routine encrypted backups is deleted when the backup retention cycle expires, and in any event within 90 days after the end of the export period. Until then it remains protected and is not used for any other purpose. We retain billing records for 7 years as required by Swedish accounting law. Retention periods by processing activity are listed on our Subprocessors page.
8. Children
The service is intended for business use and is not directed at anyone under 16. We do not knowingly collect data from children. Contact privacy@bytesafe.dev if you believe we have done so.
9. Data hosting
All customer data in the Bytesafe service is stored and processed within the European Union, by default on Scaleway infrastructure in France. We select the EU region for every subprocessor that offers a choice, and do not store customer data outside the EU/EEA. Some subprocessors are established outside the EEA and cover that with Standard Contractual Clauses.
Our websites are operated separately and hold no customer data. Some providers behind them are established outside the EEA; those transfers rely on adequacy decisions under Article 45 GDPR rather than on your consent. Our Subprocessors page lists every processor, where it processes, and the mechanism relied on for each one.
10. Changes
We may update this policy. We will notify registered users of significant changes by email or by posting a notice on the site. Questions: privacy@bytesafe.dev.